CVE-2010-4696: SQL Injection
Published Jan 18, 2011
·Updated
Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filterorder or (2) filterorderDir parameter in a comcontact action to index.php, a different vulnerability than CVE-2010-4166. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
23 affected components
Joomla Joomla\!=1.5.11
Joomla Joomla\!=1.5.13
Joomla Joomla\!=1.5.3
Joomla Joomla\!=1.5.2
Joomla Joomla\!=1.5.9
Joomla Joomla\!=1.5.18
Joomla Joomla\!=1.5.16
Joomla Joomla\!=1.5.4
Joomla Joomla\!=1.5.10
Joomla Joomla\!=1.5.7
Joomla Joomla\!=1.5.0
Joomla Joomla\!=1.5.15
Joomla Joomla\!=1.5.6
Joomla Joomla\!=1.5.1
Joomla Joomla\!=1.5.17
Joomla Joomla\!=1.5.8
Joomla Joomla\!=1.5.19
Joomla Joomla\!=1.5.21
Joomla Joomla\!=1.5.12
Joomla Joomla\!=1.5.5
Joomla Joomla\!=1.5.20
Joomla Joomla\!=1.5.15-rc
Joomla Joomla\!=1.5.14
Event History
Jan 18, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4696?
CVE-2010-4696 is classified as a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2010-4696?
To fix CVE-2010-4696, upgrade Joomla! to version 1.5.22 or later.
3
What types of vulnerabilities are described in CVE-2010-4696?
CVE-2010-4696 describes multiple SQL injection vulnerabilities.
4
Which versions of Joomla! are affected by CVE-2010-4696?
CVE-2010-4696 affects Joomla! versions prior to 1.5.22.
5
Can CVE-2010-4696 be exploited remotely?
Yes, CVE-2010-4696 can be exploited remotely by attackers.